TGViewer
Arch Arch @arch · 760 subscribers
Post #23 1.1K
⚠️JUST IN: FBI & IC3 warn of PhaaS stealing Microsoft 365 OAuth tokens

The FBI and IC3 published a joint PSA after Kali365, a Telegram marketed Phishing‑as‑a‑Service observed in April 2026, was found automating OAuth Device Authorization phishing to capture Microsoft 365 access. The phishing kit packages the full attack chain: AI-written lures, multilingual templates, dynamic device‑code generation, live cookie capture panels, and affiliate access which makes it easy for low-skill actors to run high‑volume campaigns.

Uses on‑demand device codes and clipboard tricks to remove timing issues, raising success rates.
Automates the full attack chain.
Refresh cookies provide persistent, stealthy access across services without needing passwords.


Requires user interaction (victim must paste the code).
Visible account activity or security alerts, token revocation and conditional access policies can detect or block misuse.
Reliant on OAuth/device‑flow implementations, rate limits and device code policies reduce effectiveness.


@arch
  • ❤ 3
  • 🤯 3
More from @arch
  1. Sep 9, 2026⚠️JUST IN: Trezor's e-mail provider has been breached Trezor has came out with a public st…
  2. Aug 14, 2026⚠️JUST IN: Trump Administration's new shift in U.S. cyber policy Trump has signed a nation…
  3. Aug 13, 2026⚠️JUST IN: Trezor confirmed a data breach involving 13000+ customers Trezor has come forwa…
  4. Aug 10, 2026⚠️JUST IN: Signal's developers are working on a feature which allows for new users to regi…
  5. Jul 22, 2026⚠️JUST IN: Ransomware group LAPSUS$ has announced their retirement A ransomware group LAPS…
  6. Jul 3, 2026⚠️JUST IN: A 19 year old Belgian arrested under the suspicion of running a phishing ring B…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →